Описание
Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows any network attacker to remotely trigger denial-of-service conditions and extract sensitive information. By abusing missing connection limits and timeouts, an attacker can exhaust file descriptors and kernel memory, leading to application crash or full host freeze. Additionally, verbose error responses disclose internal paths and system details (including usernames on Windows), aiding further exploitation. The issue requires no authentication or user interaction and is exploitable over the network. This vulnerability is fixed in 1.26.2.
A flaw was found in Podman Desktop. A remote attacker can exploit an unauthenticated HTTP server, which lacks proper connection limits and timeouts, to trigger denial-of-service (DoS) conditions. This can lead to application crashes or a complete host freeze. Additionally, verbose error responses from the server may disclose sensitive information, such as internal file paths and system details, including usernames on Windows systems.
Отчет
Podman Desktop is vulnerable to denial-of-service and information disclosure. An unauthenticated HTTP server, lacking proper connection limits, allows remote attackers to trigger application crashes or host freezes. Additionally, verbose error responses may expose sensitive internal paths and system details. This affects Red Hat Enterprise Linux versions shipping Podman Desktop. Red Hat Product Security has rated this vulnerability as having the severity of Important as it allows remote unauthenticated users to compromise system availability (A:H), additionally the leak of sensitive path information leakage in error message may allow the attacker to gain knowledge about the environment on which podman-desktop is running.
Меры по смягчению последствий
Restrict network access to the system running Podman Desktop. Configure a firewall to block incoming connections to the ports used by Podman Desktop's unauthenticated HTTP server from untrusted networks. For example, using firewall-cmd on Red Hat Enterprise Linux:
Replace <PORT_NUMBER> with the actual port used by Podman Desktop. This mitigation limits the attack surface and prevents remote exploitation, but may impact the ability to remotely manage or interact with Podman Desktop.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Build of Podman Desktop | podman-desktop-macos-1-0 | Affected | ||
| Red Hat Build of Podman Desktop | podman-desktop-windows-1-0 | Affected | ||
| Red Hat Build of Podman Desktop - Tech Preview | rhdesktop/rh-podman-desktop-ext-bootc-rhel10 | Will not fix | ||
| Red Hat Build of Podman Desktop - Tech Preview | rhdesktop/rh-podman-desktop-ext-openshift-local-rhel10 | Will not fix | ||
| Red Hat Build of Podman Desktop - Tech Preview | rhdesktop/rh-podman-desktop-ext-redhat-account-rhel10 | Affected | ||
| Red Hat Build of Podman Desktop - Tech Preview | rhdesktop/rh-podman-desktop-ext-rhel-rhel10 | Will not fix | ||
| Red Hat Build of Podman Desktop - Tech Preview | rhdesktop/rh-podman-desktop-ext-sandbox-rhel10 | Will not fix | ||
| Red Hat Enterprise Linux 10 | podman-desktop | Out of support scope | ||
| Red Hat Enterprise Linux 10 | rh-podman-desktop | Fixed | RHSA-2026:13867 | 05.05.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.2 High
CVSS3
Связанные уязвимости
Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows any network attacker to remotely trigger denial-of-service conditions and extract sensitive information. By abusing missing connection limits and timeouts, an attacker can exhaust file descriptors and kernel memory, leading to application crash or full host freeze. Additionally, verbose error responses disclose internal paths and system details (including usernames on Windows), aiding further exploitation. The issue requires no authentication or user interaction and is exploitable over the network. This vulnerability is fixed in 1.26.2.
Уязвимость компонента WebView HTTP Server программного средства управления и запуска OCI-контейнеров Podman, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и вызвать отказ в обслуживании
EPSS
8.2 High
CVSS3